The ScanTitan WordPress Vulnerability Scanner Online fingerprints your WordPress core, plugins, and themes, then matches each detected version against the continuously updated WPScan vulnerability database and broader CVE intelligence to identify known vulnerabilities, affected versions, severity, and available fixes.
Enter your WordPress site URL, create a free account, and start your scan.
A WordPress vulnerability scanner is an automated tool that inspects a WordPress site for known security weaknesses in its core, plugins, and themes. It fingerprints the exact version of each component, then matches those versions against a database like WPScan and the wider CVE feeds to report which ones carry known, exploitable flaws.
A version check tells you a plugin is outdated. ScanTitan tells you the CVE, the CVSS score, the HTTP evidence that confirms it, and the exact version that fixes it, so your team spends time patching, not guessing.
Whether you run one blog, a WooCommerce store, or a portfolio of client sites, ScanTitan gives you attacker-level enumeration plus authenticated depth, and it flags risky plugins even when no CVE has been published yet.
ScanTitan identifies the exact core version from the generator meta tag, readme.txt stable tag, static file paths under wp-includes, and the WordPress.org API, cross-checking multiple signals for accuracy.
The scanner detects every installed plugin and theme with its exact version by analyzing wp-content paths, CSS and JavaScript fingerprints, and stylesheet headers, including inactive components most scanners skip.
Each detected version is matched against the continuously updated WPScan vulnerability database and broader CVE intelligence, so an outdated component becomes a named vulnerability with severity context and the release that fixes it.
ScanTitan looks for the leaks an attacker grabs first: readable wp-config.php backups, database dumps, directory listing, and enumerable usernames that feed brute-force attacks.
Every finding ships with the exact request and response that confirmed it, so nothing reaches your dashboard as an unproven guess and no client can dispute it.
Findings are ranked by CVSS and real-world exploitability, each with a plain-language fix and a one-click re-scan that verifies the vulnerability is closed.
A 12-site agency ran ScanTitan across its whole portfolio and found three sites running a Revolution Slider build with a public arbitrary-file-download exploit. All three were patched the same afternoon, before a single site was compromised.
Most free WordPress scanners run one way: unauthenticated, seeing only what a logged-out visitor sees. That is a useful attacker’s-eye view, but it misses everything behind the login. ScanTitan runs both, so you choose the depth.
Passive scan fingerprints core, plugins, and themes from public signals with low impact, safe on production and ideal for a fast portfolio sweep. Authenticated scan logs in and reaches the admin surface: inactive plugins, admin-only pages, and configuration a logged-out visitor never sees, exactly what a compromised-credential attacker would reach.
No noise, Aggressive enumeration can send thousands of requests, so ScanTitan rate-limits deep scans and schedules them off-peak. You get attacker-level depth without tripping your own intrusion prevention.
Every finding ships with a plain-language fix tailored to the component: the exact plugin version to update to, the config to change, or the file to remove. Not a generic CVE link, a specific next step.
After you apply the fix, trigger a one-click re-scan. ScanTitan confirms the vulnerable version is gone and attaches a clean-scan record to the issue, which doubles as audit and client evidence that the problem was found and fixed.
Clean stays clean, Scheduled scanning re-checks every component against the latest WPScan data, so the day a new plugin CVE drops, the sites running it get flagged automatically, not at your next manual review.
WordPress core is actively maintained, while most known WordPress vulnerabilities are found in third-party plugins and themes. That makes component visibility critical: a scanner needs to identify the exact plugin, theme, and core versions in use, then match them against current vulnerability intelligence.
| WordPress component | 2026 vulnerabilities | Share | What ScanTitan checks |
|---|---|---|---|
| Plugins | 7,083 | 88% | Identifies installed plugin versions and checks them against current WPScan vulnerability data and broader CVE intelligence. |
| Themes | 930 | 12% | Checks detected active and inactive theme versions for known security vulnerabilities and applicable fixes. |
| WordPress Core | 19 | <1% | Identifies the exact WordPress core version and checks it against applicable vulnerability and security-advisory data. |
For a deeper breakdown of plugin vulnerability volume, severity, patch availability, and exploitation trends, see our WordPress Plugin Vulnerability Statistics 2026 research.
Active installation counts reflect current WordPress.org figures where available and may differ from the number of sites that were running an affected version when each vulnerability was disclosed.
| Vulnerability | CVE | Affected plugin | Current active installs | Severity |
|---|---|---|---|---|
| LiteSpeed Cache privilege escalation | CVE-2024-28000 | LiteSpeed Cache ≤ 6.3.0.1 | 7,000,000+ | CVSS 9.8 |
| WooPayments authentication bypass | CVE-2023-28121 | WooPayments ≤ 5.6.1 | 800,000+ | CVSS 9.8 |
| WP Automatic SQL injection | CVE-2024-27956 | WP Automatic ≤ 3.92.0 | — | CVSS 9.9 |
| Modular DS privilege escalation | CVE-2026-23550 | Modular DS ≤ 2.5.1 | 40,000+ | CVSS 10.0 |
| Breeze Cache arbitrary file upload | CVE-2026-3844 | Breeze Cache ≤ 2.4.4 | 300,000+ | CVSS 9.8 |
Exact core version from the generator tag, readme.txt, wp-includes paths, and the WordPress.org API, cross-checked and matched to core CVEs with CVSS scores.
Every plugin and version enumerated and matched to WPScan and CVEs, covering WooCommerce, Elementor, Yoast SEO, Contact Form 7, ACF, Jetpack, and thousands more.
Active and inactive themes detected from stylesheet headers and file paths, with each version matched to known theme CVEs and the patch that resolves it.
Flags plugins and themes with no published CVE but no updates in years or removed from the directory. An unmaintained component is a latent exposure, scored as elevated risk.
Detects readable wp-config.php backups, database dumps, leftover installer files, and directory listing on wp-content paths, each with the URL and HTTP response that proves it.
Finds publicly enumerable usernames that feed the brute-force attacks behind 16% of WordPress compromises, so you can close the login surface before it is sprayed.
Every detected version matched against the WPScan database, the most authoritative WordPress vulnerability catalog, plus the wider CVE and NVD feeds, updated continuously.
Multiple independent detection methods, generator tag, static file analysis, path-based checks, WordPress.org API, and readme.txt parsing, for high version accuracy.
Every finding includes the HTTP request and response that confirmed it. No probability guesses, so you or your client can act and verify without second-guessing.
Exact core version from the generator tag, readme.txt, wp-includes paths, and the WordPress.org API, cross-checked and matched to core CVEs with CVSS scores.
Every plugin and version enumerated and matched to WPScan and CVEs, covering WooCommerce, Elementor, Yoast SEO, Contact Form 7, ACF, Jetpack, and thousands more.
Active and inactive themes detected from stylesheet headers and file paths, with each version matched to known theme CVEs and the patch that resolves it.
Detects readable wp-config.php backups, database dumps, leftover installer files, and directory listing on wp-content paths, each with the URL and HTTP response that proves it.
Finds publicly enumerable usernames that feed the brute-force attacks behind 16% of WordPress compromises, so you can close the login surface before it is sprayed.
Flags plugins and themes with no published CVE but no updates in years or removed from the directory. An unmaintained component is a latent exposure, scored as elevated risk.
Every detected version matched against the WPScan database, the most authoritative WordPress vulnerability catalog, plus the wider CVE and NVD feeds, updated continuously.
Multiple independent detection methods, generator tag, static file analysis, path-based checks, WordPress.org API, and readme.txt parsing, for high version accuracy.
Every finding includes the HTTP request and response that confirmed it. No probability guesses, so you or your client can act and verify without second-guessing.
A WordPress vulnerability scanner finds weaknesses before they are exploited: outdated plugins, unpatched core, exposed config, the open doors. It is proactive and prevents the compromise.
A malware scanner finds the damage after a breach: injected backdoors, SEO spam, redirect scripts, the intruder already inside. It is reactive and cleans up after one. Running only a malware scanner is like checking for burglars without ever locking the door.
Proactive. Finds exploitable plugins, themes, core, and exposed files so you can close them before an attacker gets in.
Reactive. Detects backdoors, SEO spam, and redirects on an already-compromised site. See ScanTitan malware removal.
Vulnerability scanning locks the doors; malware scanning cleans up if someone got in. ScanTitan covers both under one roof.
WordPress core, every plugin, and every theme with its exact version and vulnerable status.
CVE ID, CVSS 3.1 score, exploit availability, and the exact version that patches it.
Request sent and response received for each finding. Fully reproducible, dispute-proof.
Unmaintained or removed plugins and themes scored as elevated risk even with no CVE.
A specific fix per finding, followed by a one-click re-scan that verifies it is closed.
Agency-ready reports that show what was found, what was fixed, and when.
# Scan a WordPress site, authenticated deep scan curl -X POST https://api.scantitan.com/v1/wp-scans \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "target": "https://client-blog.com", "scan_type": "authenticated", "notify": ["slack","email"] }' # Response { "scan_id": "wp_4a8c2f", "status": "queued", "plugins_found": 24 }- schedule: weekly targets: all_sites alert_on: new_cve,critical,high report: white_label_pdfAll sites, one screen
Daily / weekly / monthly
Instant vuln alerts
Clean-to-vulnerable alerts
Auto-create tickets
Client-ready reports
Authenticated access
Any tool via JSON
Trigger + pull results
Real outcomes from real scans.
Three client sites ran a Revolution Slider build with a public arbitrary-file-download exploit that reads wp-config.php. The agency patched all three the same afternoon.
3
1 aft
0
A WooCommerce extension was running a version with a known SQL injection CVE. ScanTitan flagged it with HTTP evidence and the exact patch version before any customer data was touched.
1
2h
0
Newly disclosed plugin CVEs sat unpatched for weeks across a large site network. Scheduled portfolio scanning now flags every affected site the day a CVE is published.
80
<24h
1
A leftover wp-config.php.bak in the web root exposed database credentials in plaintext. ScanTitan surfaced it with the exact URL and response, and the owner removed it immediately.
1
5 min
0
July 2026
ScanTitan now scores plugins and themes with no published CVE but no updates in years, or removed from the WordPress.org directory, as elevated risk, so you can replace latent exposures before a CVE exists.
May 2026
Authenticated scans now enumerate installed-but-inactive plugins and themes, catching vulnerable components that a logged-out scan never sees.
March 2026
Continuous synchronization with the WPScan vulnerability database means a plugin gets re-flagged the day a new CVE is published, and your scheduled scan catches it automatically.
January 2026
Agencies can now scan and monitor an entire portfolio from one dashboard, with white-label PDF reports and per-site alerting on new vulnerabilities.
| ScanTitan | WPScan | Pentest-Tools | WPSec | HackerTarget | |
|---|---|---|---|---|---|
| Core, plugin, theme CVE detection | ✓ | ✓ | ✓ | ✓ | ✓ |
| Authenticated scanning | ✓ | CLI | ✓ | Partial | Partial |
| Proof-based HTTP evidence | ✓ | ✗ | ✓ | ✗ | ✗ |
| Risk score for plugins with no CVE | ✓ | ✗ | ✗ | ✓ | ✗ |
| Plain-language fix + re-scan | ✓ | Partial | Partial | ✓ | ✗ |
| Multi-site / agency dashboard | ✓ | Enterprise | Partial | ✓ | ✓ |
| Vulnerability + malware in one platform | ✓ | ✗ | ✗ | ✗ | ✗ |
| Entry point | Free scan | Free DB / API | 7-day trial | Free basic | Free basic |
4.8
G2
4.9
"We run 40 client WordPress sites. ScanTitan flagged a critical plugin CVE across three of them the day it was disclosed. The white-label reports are now part of every client's monthly care plan."
A WordPress vulnerability scanner is an automated tool that inspects a WordPress site for known security weaknesses in its core, plugins, and themes. It fingerprints the version of each component, then matches those versions against a database like WPScan and the wider CVE feeds to report which carry known, exploitable flaws. Unlike a malware scanner, which detects code that is already malicious, a vulnerability scanner finds the outdated or misconfigured components an attacker could exploit before any breach happens. ScanTitan adds proof for every finding and reaches the authenticated surface most free scanners cannot.
Enter your site URL into ScanTitan and run a passive scan, which fingerprints your core, plugins, and themes from the outside in a couple of minutes with no installation. For deeper coverage, connect authenticated access so the scanner reaches admin-only pages and inactive plugins. ScanTitan then matches every detected version against the WPScan database and 100,000+ CVEs, reports each finding with its CVSS score and HTTP evidence, and gives a plain-language fix. You can schedule scans so newly disclosed vulnerabilities are caught automatically.
Plugins account for more than half of all WordPress compromises because they are third-party code of wildly varying quality, installed with high privileges, and often left unmaintained. WordPress core is patched fast and auto-updates by default, but a plugin from a small developer may go months or years without a security fix, and site owners rarely track which of their two dozen plugins is behind. Attackers scan the internet for specific vulnerable plugin versions with public exploits, so a scanner that checks only core misses the biggest source of real-world breaches.
A passive scan is low-impact and safe on production at any time; it sends a small number of requests and reads public signals. A deep authenticated scan that enumerates thousands of plugin and theme paths generates far more requests, which is why ScanTitan rate-limits it and lets you schedule it off-peak. The scanner uses non-destructive checks: it confirms a vulnerable version exists without exploiting it, so it never modifies your data or takes your site down.
Continuously, or at minimum weekly. New plugin and theme CVEs are published constantly, so a site that scanned clean last month can become exposed today without a single change on your end, simply because a vulnerability was disclosed in a plugin you already use. A reliable website vulnerability scanner like ScanTitan continuously re-checks your components against the latest vulnerability data and alerts you the moment a previously secure site becomes vulnerable. For agencies, automated portfolio scanning is the only realistic way to keep pace with the volume of WordPress vulnerability disclosures.
Yes, to the extent they can be fingerprinted and have known vulnerabilities. ScanTitan detects premium plugins like Advanced Custom Fields Pro, Elementor Pro, and WooCommerce extensions by their file signatures and version markers, then matches them against the WPScan database and CVE feeds the same way it handles free plugins. For fully custom plugins with no public record, it still flags risk signals like an unmaintained codebase and exposed files, and the authenticated web-application scan on the parent hub tests the custom code itself for issues like SQL injection and XSS.
A vulnerability scan is proactive: it finds the outdated plugins, unpatched core, and exposed files an attacker could exploit, so you close them before a breach. A malware scan is reactive: it detects malicious code, such as backdoors, SEO spam, and redirects, that is already on a compromised site. Both matter, and running only one leaves a gap. ScanTitan covers vulnerability scanning here and pairs it with a dedicated malware removal service, so the same platform handles both closing the doors and cleaning up if someone got in.
No. The passive and unauthenticated scans run entirely from ScanTitan's side, so you just enter your URL and get results, no installation required. If you want authenticated depth that reaches admin-only pages and inactive plugins, you can connect access with a lightweight WordPress plugin or credentials, but that is optional. The external scan alone already covers core, active plugins, themes, exposed files, and user enumeration, which is where most real-world WordPress compromises begin.
OSCP · CISSP · 12 years in web application security · Author profile →